Web App Penetration Test (OWASP, Single App)

Web App Penetration Test (OWASP, Single App) - Image 1

About This Service

TL;DR

A focused, manual penetration test of one web application, tested against the OWASP Top 10. Delivered by a vetted, admin-reviewed UAE specialist on Nadbook - contact them directly on WhatsApp, phone, or email, with zero platform commission.

Web App Penetration Test (OWASP Top 10, Single App)

A focused, manual penetration test of one web application, tested against the OWASP Top 10. I go beyond an automated scanner: authentication and session management, broken access control and IDOR, injection (SQL/NoSQL/command), cross-site scripting, security misconfiguration, sensitive-data exposure, SSRF and the business-logic flaws scanners miss. The work targets your app's real attack surface - login, user roles, payment or booking flows, file uploads and APIs - so you find out where a real attacker would actually get in.

You receive a severity-rated report (Critical/High/Medium/Low with CVSS-style scoring) written for both engineers and management: each finding has a clear proof-of-concept, the affected endpoint, the impact, and step-by-step fix guidance - plus an executive summary suitable for clients, partners or compliance reviews. After your team patches, a free retest of the reported issues is included to confirm the fixes hold. I work with SMEs, startups and free-zone/mainland businesses across Dubai, Abu Dhabi and Sharjah.

This is a fixed-scope, fixed-price test of a single web application. If you need broad VAPT across network, mobile, APIs and multiple systems, that's my separate VAPT gig - this one is the accessible, well-defined option for one web app. All testing is strictly authorized only: I work under a signed scope and rules-of-engagement document covering exactly which app and environment, the test window and the methods allowed, and I never test any system without the owner's written permission.

What's included

  • OWASP Top 10 coverage - Manual testing of the full OWASP Top 10 categories
  • Auth + access-control tests - Login, sessions, roles, IDOR and privilege escalation
  • Severity-rated report - Critical/High/Medium/Low with CVSS-style scoring
  • PoC + fix guidance - Reproducible proof-of-concept and step-by-step remediation
  • Free retest - One retest of reported issues after you patch
  • Exec + technical summary - Report suitable for engineers and for compliance reviews

How it works

  1. 1
    Scope + authorize

    Agree the single app, environment and test window; sign scope and rules of engagement

  2. 2
    Test + document

    Manual OWASP-based testing of the app, recording each finding with a PoC

  3. 3
    Report + retest

    Deliver the severity-rated report, then retest the fixes you ship

Why work with me

With meTypical agency
Fixed scope and priceOpen-ended quote
Retest includedCharged extra
Business-logic testingManualScanner only
Compliance-ready report

Frequently asked questions

How long does "Web App Penetration Test (OWASP, Single App)" take to deliver?

Typical delivery is 10 days from order confirmation. Nadeem Khan will share an exact timeline when you make first contact.

How do I hire Nadeem Khan on Nadbook?

Use the WhatsApp, phone, or email button on this page to reach out directly. Nadbook is a contact-first marketplace - there are no platform fees and the seller handles delivery directly.

Reviews (0)

No reviews yet. Worked with this seller? Be the first to leave one.

Leave a review

Reviews are checked by our team before they appear.

Related services

Other vetted UAE specialists with similar work.